-
Notifications
You must be signed in to change notification settings - Fork 29.1k
[Feature] Allow to clear Service Worker cache #24008
Copy link
Copy link
Closed as not planned
Labels
area: service-workerIssues related to the @angular/service-worker packageIssues related to the @angular/service-worker packagefeatureLabel used to distinguish feature request from other issuesLabel used to distinguish feature request from other issuesfeature: under considerationFeature request for which voting has completed and the request is now under considerationFeature request for which voting has completed and the request is now under consideration
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
area: service-workerIssues related to the @angular/service-worker packageIssues related to the @angular/service-worker packagefeatureLabel used to distinguish feature request from other issuesLabel used to distinguish feature request from other issuesfeature: under considerationFeature request for which voting has completed and the request is now under considerationFeature request for which voting has completed and the request is now under consideration
I'm submitting a...
Current behavior
As a developer, I clear the cookies, data and relevant user information from the browser when the user logs out.
For privacy and security reasons and to avoid keeping relevant data in the browser's cache, I delete all the relevant data of the user from the cookies and localStorage.
However I cannot do the same from the service worker cache.
Expected behavior
I'd like to be able to clear the Service Worker cache whenever a user logs out, to make sure no other user has access to the cache in any way.
This could be added as a function in the Service Worker provider.
What is the motivation / use case for changing the behavior?
A problem is that if a user [bob] does log in with his/her user account after a logout from another user [alice], the cache of the Service Worker might answer with data from alice's requests, having a privacy problem here... The only difference between the requests is the access Token, and is set in the header, which is not taken in account when caching in the service worker. Thus a properly made request while being offline, would be able to answer the data from another user.
Another problem is that a user could access the cache from the browser web tools and check the contents of the cache, even after the user has logged out.
Environment